The reportThe Norman SandBox Analyzer summary is a description of the files behavior and action performed in the target victim’s object and elements setup to enable external communication.
This report is a subset of the API log that generates a detailed overview of the files action command by command.
Example of a NSA summary
reportThe诺曼底沙盒分析仪总结是文件在目标受害者的对象和元素设定和行动的描述进行的行为使能外部通讯。这个报告是由命令引起文件行动命令详细的概要API日志的一个子集。 NSA总结的例子
D:VIRUSMYTEST.EX_ : W32/Backdoor
====> Sandbox output:
[ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO -
REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Display message box (sample) : sample, te amo!.
* Display message box (KERN32) : KERN32, te amo!.
* File length: 58368 bytes.
* MD5 hash: 60a8d2e41147f48364e1eb3729ac53fb.
[ Changes to filesystem ]
* Deletes file C:WINDOWSSYSTEM32kern32.exe.
* Creates file C:WINDOWSSYSTEM32kern32.exe.
[ Changes to registry ]
* Creates key "HKLMSoftwareMicrosoftWindowsCurrentVersionRunOnce".
* Sets value "kernel32"="C:WINDOWSSYSTEM32kern32.exe -sys" in key "HKLMSoftwareMicrosoftWindowsCurrentVersionRunOnce".
[ Changes to system settings ]
* Creates WindowsHook monitoring keyboard activity.
[ Network services ]
* Connects to "200.223.3.130" on port 6667 (TCP).
* Connects to IRC server.
* IRC: Uses nickname CurrentUser[FRK][19].
* IRC: Uses username SErVERINO.
* IRC: Joins channel #Sl4cK_r0oT.
[ Process/window information ]
* Creates a mutex ZZM9H9YY.
* Creates a mutex SrVFrK.
This is a short example of an API logIf you look closely you will see that the API log is from the same file as the SandBox summary above.
这是您看您严密地看见API logIf的一个短的例子API日志是从文件和上面沙盒总结一样。
KERNEL32!CopyFileA ("C:WINDOWSSYSTEM32KERN32.EXE",
"C:WINDOWSSYSTEM32kern32.exe",0x00000000)
KERNEL32!GetFileAttributesA ("C:WINDOWSSYSTEM32kern32.exe")
KERNEL32!GetFileAttributesA ("C:WINDOWSSYSTEM32kern32.exe")
KERNEL32!CreateFileA ("C:WINDOWSSYSTEM32KERN32.EXE",0x80000000,
0x00000000,0x00000000,0x00000003,0x00000000,0x00000000)
KERNEL32!SetFileAttributesA ("C:WINDOWSSYSTEM32kern32.exe",0x00000006)
ADVAPI32!RegCreateKeyExA (0x80000002,"SoftwareMicrosoftWindows
CurrentVersionRunOnce",0x00000000,NULL,0x00000000,0x000F003F,0x00000000,
0x4FD01154,0x00000000)
ADVAPI32!RegSetValueExA (0x7200214B,"kernel32",0x00000000,0x00000001,
"C:WINDOWSSYSTEM32kern32.exe -sys",0x00000023)
ADVAPI32!RegCloseKey (0x7200214B)
KERNEL32!CreateMutexA (0x00000000,0x00000000,"SrVFrK")
KERNEL32!GetLastError ()
KERNEL32!CreateThread (0x00000000,0x00000000,0x004027B9,0x74116F00,
0x00000004,0x74116F00)
System requirements- Pentium III or higher
- 512 Mb Ram or more
- At least 50 Mb free hard drive space
- Operating System: Windows 2000/2003 or XP.
More information - testing or purchasing the productClick here and fill in the form to purchase or test the product, or to request more information.
Click Norman SandBox Analyzer - Return on investment (ROI) calculator if you are interesting in calculating your savings compared to using analysts.
更多信息-测试或购买productClick这里和填写形式购买或测试产品,或者请求更多信息。点击诺曼底沙盒分析仪- (ROI)计算器的回收投资,如果您是有趣在计算您的储款与使用分析员比较。
[ 本帖最后由 jeccci5 于 2008-4-16 20:05 编辑 ] |